Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 206

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
In reversal, Trump backs Nexstar's proposed acquisition of Tegna
The new Bilt 2.0 cards are open for application. Here's how to decide which card is right for you
Here are the 5 big things we're watching in the stock market this week
Epstein files: UK PM Starmer's top aide McSweeney quits over Mandelson scandal
Elon Musk wants to be a trillionaire — here's how SpaceX may get him there
Washington Post publisher Will Lewis announces departure, following mass layoffs
NFL plans to have discussions with partners outside of core media for live games, media chief says
Federal judge orders Fulton County Georgia election case documents unsealed by Tuesday
Japan's Nikkei 225 skyrockets over 5% to hit record highs as Takaichi secures historic mandate
Epstein files: Congressional lawmakers call for Trump Commerce chief Lutnick to resign, or be fired